Live data from Hacker News

Slack enables customers to control their encryption keys in enterprise version

techcrunch.com

151–160 of 178 posts

Re: Slack enables customers to control their encryption keys in enterprise version

#151
post #100
post #91

Earlier quoted context omitted.

Can you elaborate on why you are asking how a chatroom service compares to a webapp framework?

You're definitely confusing with Symfony, the PHP framework. As others pointed out, Symphony is a Slack competitor.

[deleted]

Re: Slack enables customers to control their encryption keys in enterprise version

#152

Earlier quoted context omitted.

Sure, but that fixes it for you, not anyone else. What's the point when the person you're talking to went offline because they went through a tunnel or momentarily closed their laptop when you sent the message? This classic HN idea that people only use Slack over IRC because it looks better/easier is a reminder of nerd hubris that prevents one from understanding people and products.

People do use Slack because it looks better and is easier to use.... the features you're talking about are possible with IRC, it just requires work that the average consumer isn't willing to do. The other half of the equation is that IRC is better in ways that consumers don't care about, yourself included.

Can you deploy irc in a way that meets or exceeds the features provided by slack to an enterprise with thousands of users? And then teach Joanne from accounting how to use it?

Re: Slack enables customers to control their encryption keys in enterprise version

#153
post #100
post #91

Earlier quoted context omitted.

Can you elaborate on why you are asking how a chatroom service compares to a webapp framework?

You're definitely confusing with Symfony, the PHP framework. As others pointed out, Symphony is a Slack competitor.

I would still say Symphony’s target is Bloomberg. Despite Symphony’s good progress so far, Bloomberg are still far ahead in market share and their network is a great moat which makes it very hard to substitute, also given that onboarding new platforms across financial firms is a huge challenge even when you aren’t pushing against network effects benefiting your main competitor.

Re: Slack enables customers to control their encryption keys in enterprise version

#154
post #58

Earlier quoted context omitted.

The article says it’s only open to enterprise customers. Computing freedom you have to pay a ton for is not really freedom. It’s really not even close to the control of IRC.

Is it not worth Linux running on mainframes because mainframes are expensive? Is it not worth Kerberos being free software because the only real users of Kerberos are enterprises? Computing freedom for anyone is computing freedom, and contributes to a norm of user control instead of service provider control. This step is a very small step, and it only affects a few users. But it's still a step in the right direction.…

> Is it not worth Linux running on mainframes because mainframes are expensive?

Honest question: what is it worth to me? I don't but into this "any linux usage is a win" mentality. Linux being used on tivos is worthless to me (https://www.gnu.org/proprietary/proprietary-tyrants.en.html), and it's hard to see why Linux running on hardware I will never have the opportunity to own should be worth anything to me either. Am I expected to cheer for the linux team no matter the circumstance?

Re: Slack enables customers to control their encryption keys in enterprise version

#155
post #103

The title of this post makes it sound like a bad thing, but in regulated industries like Finance, firms are required to produce chat transcripts of the traders to regulators. Slack would be unusable in this industry if the firms could not capture all of the chat logs.

[deleted]

Re: Slack enables customers to control their encryption keys in enterprise version

#156

Only available for an "additional fee" for Enterprise users. Cheeky. Also, Slack, I'd like a native MacOS app please.

It's only needed by large, highly regulated businesses, and it only works for self-hosting obviously.

Slack doesn't provide a self-hosting option at any tier. This allows you to host the encryption key in your own AWS account's KMS service, which Slack then (running in Slack's own AWS account) then queries.

Re: Slack enables customers to control their encryption keys in enterprise version

#157
post #58

Earlier quoted context omitted.

Is it not worth Linux running on mainframes because mainframes are expensive? Is it not worth Kerberos being free software because the only real users of Kerberos are enterprises? Computing freedom for anyone is computing freedom, and contributes to a norm of user control instead of service provider control. This step is a very small step, and it only affects a few users. But it's still a step in the right direction.…

Both of the technologies you named as examples are free and open. Anyone can inspect them and deploy them on their own. Slack isn’t like that unfortunately. This is a move to add another feature that will attract enterprise customers, I would doubt that even Slack themselves would proclaim this as a move towards greater software freedom.

> Anyone can inspect them and deploy them on their own

That's what I don't get from reading this thread. Like you said, Kerberos does have its uses outside enterprise deployments, and if you want authenticated/encrypted NFS for whatever reason it's really one of your only options.

Re: Slack enables customers to control their encryption keys in enterprise version

#158
post #145
post #83

Earlier quoted context omitted.

Yeah I don't really care about Slack, it's banned at work. However, this pattern is good and IMHO should be adopted by SaaS orgs that want to appeal to enterprise/regulated customers. We have a few vendors that we're sort of pressing in this direction, and a few have come to us with similar architectural proposals to address GDPR. Specific to AWS it would be even better of the service allowed for the customer to host…

> Specific to AWS it would be even better of the service allowed for the customer to host the CMK in their own account so they can choose to import key material if they like. Looks like it does, based on https://aws.amazon.com/blogs/apn/control-access-to-your-data... "With Slack EKM, you can use KMS in your own AWS account to create a Customer Master Key (CMK) that always stays under your control. Then, using key pol…

That's cool! Thank you for digging into it.

Re: Slack enables customers to control their encryption keys in enterprise version

#159
post #55

Earlier quoted context omitted.

"But generally, an entity that has keys can forge messages." It depends on how it's structured, and with the most natural structure, this wouldn't be true. You'd be able to forge a message with the keys to exactly the same degree that you can forge a message coming from your coworker in Slack right now; short of social engineering to steal their password, anything else that would allow you to do that right now would…

Why do you believe employees are worried about the actions of Slack instead of the actions of their own employer? This change allows companies to spy on employees.

No it doesn't! Employers have been able to read messages on Slack for ages now.
Post reply on HN